First published: Tue Feb 26 2019(Updated: )
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU glibc | <=2.29 | |
Netapp Cloud Backup | ||
NetApp ONTAP Select Deploy administration utility | ||
Netapp Steelstore Cloud Integrated Storage |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20796 is a vulnerability in the GNU C Library (glibc) through version 2.29 that allows for uncontrolled recursion, leading to potential denial of service or arbitrary code execution.
CVE-2018-20796 can affect systems that rely on the affected versions of the GNU C Library (glibc), potentially leading to denial of service or arbitrary code execution.
CVE-2018-20796 has a severity rating of 7.5 (high).
Versions of GNU glibc up to and including 2.29, NetApp Cloud Backup, NetApp ONTAP Select Deploy administration utility, and NetApp Steelstore Cloud Integrated Storage are affected by CVE-2018-20796.
To mitigate CVE-2018-20796, it is recommended to upgrade to a patched version of the GNU C Library (glibc), if available, or follow the guidance provided by the software vendor for the affected software.